VerbatimParliament, as it happens

Government Departments: Data Protection

Asked by Mr Andrew SnowdenConservativeDepartment for Science, Innovation and TechnologyTabled Answered 12 June 2025UIN 55160

The question

To ask the Secretary of State for Science, Innovation and Technology, what steps he is taking to protect people's data held by government departments.

Answered by Feryal Clark

All Departments must adhere to the UK Data Protection legislation to protect personal data held by their departments. All departments are controllers of the personal data they hold and are individually responsible for demonstrating compliance with the data protection principles, and take appropriate technical and organisational measures in line with the UK GDPR. Under the same legislation, all departments are required to appoint a data protection officer (DPO), who must be an adequately resourced expert in data protection to monitor internal compliance, inform and advise on the department’s data protection obligations, provide advice regarding Data Protection Impact Assessments (DPIAs) and act as a contact point for data subjects and the Information Commissioner’s Office.

The DPO must be independent and report to the highest management level.

To reinforce cross government data sharing for consistent application of safeguards, the Government Digital Service runs the Data Sharing Network of Experts to bring together data protection and data governance professionals. There is also a cross government Data Protection Officers Network.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim